OT/ICS Standards Reference

Maintain an up-to-date inventory of information assets.

Reference details and direct document links for maintaining inventories of information assets such as business data, intellectual property, customer information, contracts, security logs, metadata, operational data, financial records, historian data, and OT process information.

5

Control / Question

Maintain an up-to-date inventory of information assets. Information assets should be inventoried and managed based on their business, operational, cybersecurity, privacy, legal, and safety significance.

C2M2 ASSET-1b (supplied) Closest exact C2M2: ASSET-2a NIST CSF ID.AM-01 NIST CSF ID.AM-02 NIST CSF ID.AM-04 NIST CSF ID.AM-07 NIST SP 800-82r3 ID.AM NIST SP 800-53 CM-8 ISA/IEC 62443 references
DOE C2M2 v2.1

ASSET-2a — Information Asset Inventory

Section 6.1, Asset, Change, and Configuration Management (ASSET), Objective 2

Relevant requirement: Information assets that are important to the delivery of the function, for example SCADA set points and customer information, are inventoried, at least in an ad hoc manner.

This is the closest exact C2M2 practice for information-asset inventory. The supplied ASSET-1b reference is IT/OT asset inventory maturity, not the main information-asset practice.
DOE C2M2 v2.1

ASSET-1b — IT/OT Asset Inventory Scope Expansion

Section 6.1, Asset, Change, and Configuration Management (ASSET), Objective 1

Relevant requirement: The IT and OT asset inventory includes assets within the function that may be leveraged to achieve a threat objective.

Preserved from the supplied mapping; useful where systems, repositories, historians, logs, or platforms can be leveraged to access or manipulate information assets.
NIST Cybersecurity Framework 2.0

ID.AM-01, ID.AM-02, ID.AM-04, ID.AM-07

Appendix A, CSF Core, IDENTIFY Function

Relevant requirement: Inventories of hardware, software, services, systems, supplier-provided services, data, and corresponding metadata for designated data types are maintained.

Use these outcomes to require inventory of data/information assets and the systems, services, and suppliers that store, process, transmit, or manage them.
NIST SP 800-82 Rev. 3

ID.AM — OT Asset and Data Management Guidance

Section 6.1.1, Asset Management (ID.AM)

Relevant requirement: Asset management identifies and manages data, personnel, devices, systems, and facilities based on their relative importance; data flows and information types should be identified.

This links information assets to OT systems, data flows, historians, set points, logs, metadata, and operational data handling.
NIST SP 800-53 Rev. 5

CM-8 — System Component Inventory

Configuration Management control family

Relevant requirement: Develop and document an inventory of system components that accurately reflects the system and includes information necessary for accountability.

CM-8 primarily inventories system components, but supports information-asset accountability by tying data repositories and processing locations to specific systems and owners.
ISA/IEC 62443 References

62443-3-3 SR 1.2 / SR 7.8 and 62443-2-1 SPE-2, 7.2

ISA/IEC 62443 series

Relevant requirement: The cited 62443 references support industrial-control-system security requirements and asset-owner security-program expectations.

Use official ISA/IEC landing pages for the authoritative standard references; the full standards are commercial/copyrighted documents.

Assessment focus